VYPR

Simple CMS

by Simple CMS

CVEs (143)

  • CVE-2018-10030HigApr 11, 2018
    risk 0.57cvss 8.8epss 0.00

    CMS Made Simple (aka CMSMS) 2.2.7 has CSRF in admin/siteprefs.php.

  • CVE-2018-1000092HigMar 13, 2018
    risk 0.57cvss 8.8epss 0.00

    CMS Made Simple version versions 2.2.5 contains a Cross ite Request Forgery (CSRF) vulnerability in Admin profile page that can result in Details can be found here http://dev.cmsmadesimple.org/bug/view/11715. This attack appear to be exploitable via A specially crafted web page.…

  • CVE-2021-47918HigFeb 1, 2026
    risk 0.53cvss 8.1epss 0.01

    Simple CMS 2.1 contains a remote SQL injection vulnerability that allows privileged attackers to inject unfiltered SQL commands in the users module. Attackers can exploit unvalidated input parameters in the admin.php file to compromise the database management system and web…

  • CVE-2018-1000094HigMar 13, 2018
    risk 0.53cvss 7.2epss 0.39

    CMS Made Simple version 2.2.5 contains a Remote Code Execution vulnerability in File Manager that can result in Allows an authenticated admin that has access to the file manager to execute code on the server. This attack appear to be exploitable via File upload -> copy to any…

  • CVE-2018-7448HigFeb 26, 2018
    risk 0.53cvss 7.5epss 0.13

    Remote code execution vulnerability in /cmsms-2.1.6-install.php/index.php in CMS Made Simple version 2.1.6 allows remote attackers to inject arbitrary PHP code via the "timezone" parameter in step 4 of a fresh installation procedure.

  • CVE-2016-7904HigJan 16, 2017
    risk 0.52cvss 8.0epss 0.01

    Cross-site request forgery (CSRF) vulnerability in CMS Made Simple before 2.1.6 allows remote attackers to hijack the authentication of administrators for requests that create accounts via an admin/adduser.php request.

  • CVE-2020-17462HigAug 14, 2020
    risk 0.51cvss 7.8epss 0.01

    CMS Made Simple 2.2.14 allows Authenticated Arbitrary File Upload because the File Manager does not block .ptar files, a related issue to CVE-2017-16798.

  • CVE-2020-10682HigMar 20, 2020
    risk 0.51cvss 7.8epss 0.02

    The Filemanager in CMS Made Simple 2.2.13 allows remote code execution via a .php.jpegd JPEG file, as demonstrated by m1_files[] to admin/moduleinterface.php. The file should be sent as application/octet-stream and contain PHP code (it need not be a valid JPEG file).

  • CVE-2018-10517HigApr 27, 2018
    risk 0.51cvss 7.2epss 0.12

    In CMS Made Simple (CMSMS) through 2.2.7, the "module import" operation in the admin dashboard contains a remote code execution vulnerability, exploitable by an admin user, because an XML Package can contain base64-encoded PHP code in a data element.

  • CVE-2017-1000454HigJan 2, 2018
    risk 0.51cvss 7.8epss 0.01

    CMS Made Simple 2.1.6, 2.2, 2.2.1 are vulnerable to Smarty Template Injection in some core components, resulting in local file read before 2.2, and local file inclusion since 2.2.1

  • CVE-2017-8912HigMay 12, 2017
    risk 0.50cvss 7.2epss 0.03

    CMS Made Simple (CMSMS) 2.1.6 allows remote authenticated administrators to execute arbitrary PHP code via the code parameter to admin/editusertag.php, related to the CreateTagFunction and CallUserTag functions. NOTE: the vendor reportedly has stated this is "a feature, not a…

  • CVE-2019-9060HigSep 17, 2021
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in CMS Made Simple 2.2.8. It is possible to achieve unauthenticated path traversal in the CGExtensions module (in the file action.setdefaulttemplate.php) with the m1_filename parameter; and through the action.showmessage.php file, it is possible to read…

  • CVE-2018-10083HigApr 13, 2018
    risk 0.49cvss 7.5epss 0.02

    CMS Made Simple (CMSMS) through 2.2.7 contains an arbitrary file deletion vulnerability in the admin dashboard via directory traversal sequences in the val parameter within a cmd=del request, because code under modules\FilePicker does not restrict the val parameter.

  • CVE-2024-1529HigMar 12, 2024
    risk 0.48cvss 7.4epss 0.00

    Vulnerability in CMS Made Simple 2.2.14, which does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /admin/adduser.php, in multiple parameters. This vulnerability could allow a remote attacker to send a specially…

  • CVE-2024-1528HigMar 12, 2024
    risk 0.48cvss 7.4epss 0.00

    CMS Made Simple version 2.2.14, does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /admin/moduleinterface.php, in multiple parameters. This vulnerability could allow a remote attacker to send a specially crafted…

  • CVE-2025-63678HigNov 10, 2025
    risk 0.47cvss 7.2epss 0.00

    An authenticated arbitrary file upload vulnerability in the /uploads/ endpoint of CMS Made Simple Foundation File Manager v2.2.22 allows attackers with Administrator privileges to execute arbitrary code via uploading a crafted PHP file.

  • CVE-2024-27622HigMar 5, 2024
    risk 0.47cvss 7.2epss 0.02

    A remote code execution vulnerability has been identified in the User Defined Tags module of CMS Made Simple version 2.2.19 / 2.2.21. This vulnerability arises from inadequate sanitization of user-supplied input in the 'Code' section of the module. As a result, authenticated…

  • CVE-2021-28998HigMay 8, 2023
    risk 0.47cvss 7.2epss 0.01

    File upload vulnerability in CMS Made Simple through 2.2.15 allows remote authenticated attackers to gain a webshell via a crafted phar file.

  • CVE-2022-23906HigFeb 28, 2022
    risk 0.47cvss 7.2epss 0.02

    CMS Made Simple v2.2.15 was discovered to contain a Remote Command Execution (RCE) vulnerability via the upload avatar function. This vulnerability is exploited via a crafted image file.

  • CVE-2019-9059HigMar 26, 2019
    risk 0.47cvss 7.2epss 0.02

    An issue was discovered in CMS Made Simple 2.2.8. It is possible, with an administrator account, to achieve command injection by modifying the path of the e-mail executable in Mail Settings, setting "sendmail" in the "Mailer" option, and launching the "Forgot your password"…

Page 2 of 8